SV-21541r1_rule
V-19482
Deficient Integrity: Vendor’s App, Upgrade, Patch
VVoIP 1201 (GENERAL)
CAT II
10
Ensure VVoIP system applications, upgrades, and patches are digitally signed by the vendor and validated for integrity before installation.
Employ only those VVoIP system applications, upgrades, and patches that are digitally signed by the vendor. Perform the appropriate digital signature validation process to validate application and upgrade/patch integrity before installation.
Interview the IAO to validate compliance with the following requirement:
Ensure VVoIP system applications, upgrades, and patches are digitally signed by the vendor and validated for integrity before installation.
Determine if VVoIP system applications, upgrades, and patches are digitally signed by the vendor and validated for integrity before installation. Have the IAO or SA demonstrate the application and upgrade/patch integrity validation process. This is a finding if digital signatures are not validated before installation.
NOTE: This requirement addresses applications, upgrades, and patches for the overall VVoIP system infrastructure. PC based applications, upgrades, and patches are addressed separately.
V-19482
False
VVoIP 1201 (GENERAL)
Interview the IAO to validate compliance with the following requirement:
Ensure VVoIP system applications, upgrades, and patches are digitally signed by the vendor and validated for integrity before installation.
Determine if VVoIP system applications, upgrades, and patches are digitally signed by the vendor and validated for integrity before installation. Have the IAO or SA demonstrate the application and upgrade/patch integrity validation process. This is a finding if digital signatures are not validated before installation.
NOTE: This requirement addresses applications, upgrades, and patches for the overall VVoIP system infrastructure. PC based applications, upgrades, and patches are addressed separately.
I
Compromise of the supported communications or the supporting infrastructure
Information Assurance Officer
594